4 ms·
It baffles me that any router manufacturer would have the nerve to hard-code login credentials into their routers. But to be clear, for this to be pulled off r
by decisiveness 12y ago
It baffles me that any router manufacturer would have the nerve to hard-code login credentials into their routers.
But to be clear, for this to be pulled off remotely, the router must first either disable its firewall or a DNS rebind attack or some other vulnerability must be possible. In the case of a rebind, a victim must also first visit an attacker's server. What would be even more concerning is if any of the routers hard coded with these login credentials are also vulnerable to a rebind or something else by default. Many manufacturers patched the rebind vulnerability back in 2010.
- userbinator 12y agoIt baffles me that any router manufacturer would have the nerve to hard-code login credentials into their routers. I'm not advocating this practice at all, but consider that BIOS passwords could be easily bypassed with a hardcoded "default password". The one I still remember is "lkwpeter" and if you Google that one you'll find plenty more. That practice slowly faded away but many laptops' BIOS passwords are still overridable with a "manufacturer access" password that is derived from the serial number/asset tag. The history of backdoors in hardware is a long one, so I'm not surprised to see them show up in routers. D-link had one a while back, and there have been several more discovered since then. As you say, perhaps what keeps them from being exploited more is that they are not accessible from the Internet-facing side.
- whoopdedo 12y agoIt's often done to make support calls easier. You could spend a long time trying to explain to a frustrated customer how to use telnet (Type a slash... no, that's backslash. No don't type the word "slash"...) Or you could just say "let me log onto the router and fix it for you."
- decisiveness 12y agoTelnet wouldn't help if they forgot the password and it wasn't hard-coded as a back door. Also, the support tech wouldn't be able to access it remotely unless some of the things I mentioned in the original comment were true. Wouldn't it be easier to just say, "hold down the reset button on the back for 30 seconds"?
- decisiveness 12y agoTrue, hardware backdoors have been around forever. The difference here is a BIOS backdoor password has a somewhat legitimate reason. You can't just hit a reset button on your PC if you forget the BIOS credentials the way you can on your router. Also, a router being programmed like this exposes every device routed through it, whereas a BIOS backdoor only gives you access to the single device to which you have physical access. My surprise comes from the gall of the manufacturers as they should be fully aware of these implications.